
If someone asked you right now how secure your business is, what would you say?
Most small business owners in greater Boston would give some version of "probably fine." Not confident, or certain. Just probably fine. And that gap, between probably fine and actually protected, is where most incidents quietly begin.
October is Cybersecurity Awareness Month, and rather than adding to the pile of generic awareness content that shows up every year, we wanted to give you something you could actually use. Work through this checklist with your team and be honest with yourself. If you get to the end and find gaps you did not know existed, that is genuinely valuable information, and it is better to find out now than when something forces it.
1. Passwords and Password Manager
Does every account your business uses have a strong, unique password that is not shared anywhere else? If the honest answer is no or you are not completely sure, a password manager is the single fastest and most practical improvement most small businesses can make. It removes the memory burden while making sure every account has its own key.
Think about it this way: if one employee account was compromised today, how many others would fall because the same password was used elsewhere?
2. Multi-Factor Authentication
Is MFA enabled on every account that supports it, including email, cloud storage, financial accounts, and anything your team accesses remotely? A strong password is no longer enough on its own. MFA stops most account takeover attempts, even after a password has been exposed.
If an attacker had your email password right now, what is actually standing between them and full access?
3. Software and Device Updates
Are all the computers, phones, and devices your team uses running the latest available updates? Unpatched systems are one of the most consistent entry points attackers exploit because the vulnerabilities they target have often already been fixed. The patch exists. The device just never received it.
It is also worth checking whether any of your equipment has reached end of life entirely. Windows 10 reached end of support in October 2025, meaning it no longer receives security updates at all. Windows Server 2012 has been unsupported since 2023. Devices still running either of these are not just unpatched, they are permanently exposed with no fix coming.
When did someone last check that every device in your office is actually up to date?
4. Phishing Awareness
Does your team know what a phishing email looks like in 2026? Not the obvious ones with broken grammar and suspicious links, but the professionally written personalised messages that impersonate vendors, colleagues, and financial institutions convincingly enough to fool someone moving quickly through a full inbox.
If a convincing phishing email landed in someone's inbox today, would they catch it and would they know who to tell?

5. Backup Testing
Does your business have a backup in place, and when did someone last verify it actually works? An untested backup is not a safety net. It is an assumption. Businesses that discover their backup was silently failing almost always find out during a ransomware recovery, when it is far too late to do anything about it.
If your most important files disappeared tomorrow, how confident are you that they could be fully restored?
6. Former Employee Access
Are there accounts belonging to former employees that still have access to your systems, email, or cloud storage? This is one of the most common and most overlooked gaps we find when working with small businesses in Greater Boston for the first time. Offboarding is rarely handled as consistently as it should be, and the accounts that get forgotten are the ones that become entry points.
When did someone last audit who actually has access to your business systems?
7. Cyber Insurance Review
Does your business carry cyber insurance and does your current policy actually reflect the security controls you have in place today? Insurers are asking increasingly specific questions at renewal about MFA, endpoint protection, and backup practices. A policy that was accurate when it was written may not be accurate now and a claim filed against an inaccurate application can be denied at the worst possible moment.
When did you last read your policy carefully?
8. Incident Response Plan
If something went seriously wrong tomorrow morning, does your team know what to do, who to call, and in what order? An incident response plan does not need to be a lengthy document. It needs to be clear enough that the right people can follow it under pressure without having to figure it out in real time.
If ransomware hit your business at 8am on a Monday, what actually happens in the first hour?
How Did Your Business Score?
If you worked through that and felt genuinely confident about every item, your business is in better shape than most, and that is worth acknowledging.
If you found gaps or realized you did not know the answer to several of those questions, that clarity is valuable. Most small businesses never take the time to find out where they actually stand until something forces it. You just did.
Throughout October, Ekaru will be sharing practical tips on LinkedIn covering each of these areas as part of Cybersecurity Awareness Month. Follow along and share this checklist with someone on your team who would benefit from working through it.
And if you want someone to work through it with you, that is what we are here for.
At Ekaru we offer a free IT assessment for small businesses across Westford, Acton, Chelmsford, Lowell, and greater Boston. No obligation, just honest answers from a local team that genuinely cares about keeping your business protected.
